<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#esx esx-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.6</oval:schema_version>
    <oval:timestamp>2010-03-11T04:32:18.901-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:5944" version="1" class="vulnerability">
      <metadata>
        <title>VMware vCenter, ESX patch and vCenter Lab Manager cross-site scripting issues</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3731" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3731"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through 2008.4, and 2009.x before 2009.3 allow remote attackers to inject arbitrary web script or HTML via (1) wwhelp_entry.html, reachable through index.html and wwhsec.htm, (2) wwhelp/wwhimpl/api.htm, (3) wwhelp/wwhimpl/common/html/frameset.htm, (4) wwhelp/wwhimpl/common/scripts/switch.js, or (5) the window.opener component in wwhelp/wwhimpl/common/html/bookmark.htm, related to (a) unspecified parameters and (b) messages used in topic links for the bookmarking functionality.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-17T17:22:13.731-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:40.772-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:09.499-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6293"/>
        <criterion comment="Patch ESX400-200911223-UG  is not installed" test_ref="oval:org.mitre.oval:tst:11288"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6293" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 4.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:4.0"/>
        <description>The operating system installed on the system is VMware ESX Server 4.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-17T17:22:13.496-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:45.305-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:14.212-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 4.0 is installed" test_ref="oval:org.mitre.oval:tst:11154"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6722" version="1" class="vulnerability">
      <metadata>
        <title>Java Runtime Environment (JRE) Virtual Machine Lets Remote Users Read/Write Files and Execute Local Applications</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1102"/>
        <description>Unspecified vulnerability in the Virtual Machine in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "code generation."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:13.971-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:17.960-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:20.391-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6676" version="1" class="vulnerability">
      <metadata>
        <title>Java Runtime Environment LDAP Implementation Bugs Lets Remote Users Deny Service and Execute Arbitrary Code</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1093"/>
        <description>LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier does not close the connection when initialization fails, which allows remote attackers to cause a denial of service (LDAP service hang).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:10.214-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:16.778-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:12.354-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6659" version="1" class="vulnerability">
      <metadata>
        <title>Integer and Buffer Overflow Vulnerabilities in the Java Runtime Environment (JRE) "unpack200" JAR Unpacking Utility May Lead to Escalation of Privileges</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1096"/>
        <description>Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:11.448-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:15.762-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:09.937-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6643" version="1" class="vulnerability">
      <metadata>
        <title>Java Runtime Environment Buffer Overflows in unpack200 Utility Lets Remote Users Execute Arbitrary Code</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1095"/>
        <description>Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:10.823-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:15.376-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:09.658-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6642" version="1" class="vulnerability">
      <metadata>
        <title>Sun Java Runtime Environment Java Plug-in weak security</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1105" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1105"/>
        <description>The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 allows user-assisted remote attackers to cause a trusted applet to run in an older JRE version, which can be used to exploit vulnerabilities in that older version, aka CR 6706490.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:15.162-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:15.002-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:09.383-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6619" version="1" class="vulnerability">
      <metadata>
        <title>Sun Java Runtime Environment Java Plug-in crossdomain.xml information disclosure</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1106"/>
        <description>The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:15.330-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:13.563-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:07.587-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6598" version="1" class="vulnerability">
      <metadata>
        <title>Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1094"/>
        <description>Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:10.403-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:12.771-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:04.574-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6585" version="1" class="vulnerability">
      <metadata>
        <title>Sun Java Runtime Environment Java Plug-in signed applet unauthorized access</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1107"/>
        <description>The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:15.506-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:11.672-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:02.804-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6584" version="1" class="vulnerability">
      <metadata>
        <title>Sun Java Runtime Environment Java Plug-in Javascript code unauthorized access</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1104"/>
        <description>The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; and 1.4.2_19 and earlier does not prevent Javascript that is loaded from the localhost from connecting to other ports on the system, which allows user-assisted attackers to bypass intended access restrictions via LiveConnect, aka CR 6724331.  NOTE: this vulnerability can be leveraged with separate cross-site scripting (XSS) vulnerabilities for remote attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:14.905-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:11.372-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:01.707-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6542" version="1" class="vulnerability">
      <metadata>
        <title>Java Plug-in Bugs Lets Remote Users Gain Privileges</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1103" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1103"/>
        <description>Unspecified vulnerability in the Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "deserializing applets," aka CR 6646860.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:14.501-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:08.562-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:54.880-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6412" version="1" class="vulnerability">
      <metadata>
        <title>Java Runtime Environment (JRE) HTTP Server Bug Lets Remote Users Deny Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1101" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1101"/>
        <description>Unspecified vulnerability in the lightweight HTTP server implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to cause a denial of service (probably resource consumption) for a JAX-WS service endpoint via a connection without any data, which triggers a file descriptor "leak."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:13.785-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:00:58.271-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:40.078-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6288" version="1" class="vulnerability">
      <metadata>
        <title>Java Runtime Environment (JRE) Buffer Overflow in Processing Image Files and Fonts Lets Remote Users Gain Privileges on the Target System</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1097"/>
        <description>Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:12.015-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:00:54.509-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:36.285-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6224" version="1" class="vulnerability">
      <metadata>
        <title>Java Runtime Environment (JRE) Flaws in Storing and Processing Temporary Font Files Let Remote Users Deny Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1100" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1100"/>
        <description>Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:13.408-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:00:50.177-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:35.572-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6008" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow Vulnerabilities in the Java Runtime Environment (JRE) with Processing Image Files and Fonts may Allow Privileges to be Escalated</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1098" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1098"/>
        <description>Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:12.349-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:00:45.397-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:31.546-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5726" version="1" class="vulnerability">
      <metadata>
        <title>Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE)</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1099"/>
        <description>Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:12.899-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:00:39.522-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:29.460-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200910403-SG is not installed" test_ref="oval:org.mitre.oval:tst:11177"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200911223-UG is not installed" test_ref="oval:org.mitre.oval:tst:10749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6462" version="1" class="vulnerability">
      <metadata>
        <title>Sudo Supplemental Group Privilege Error Lets Certain Local Users Gain Elevated Privileges</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0034"/>
        <description>parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:53.336-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6462" date="2009-10-20T13:59:00.494-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:01:02.903-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:45.115-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6020"/>
        <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
          <criterion comment="Patch ESX400-200906411-SG is not installed" test_ref="oval:org.mitre.oval:tst:10871"/>
          <criterion comment="Patch ESX400-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10674"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6020" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 4.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:4.0"/>
        <description>The operating system installed on the system is VMware ESX Server 4.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:53.059-04:00">DRAFT</status_change>
            <status_change date="2009-10-26T04:00:04.560-04:00">INTERIM</status_change>
            <status_change date="2009-11-16T04:00:17.087-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 4.0 is installed" test_ref="oval:org.mitre.oval:tst:10828"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6074" version="1" class="vulnerability">
      <metadata>
        <title>cURL/libcURL HTTP 'Location:' Redirect Security Bypass Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0037" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0037"/>
        <description>The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:00.140-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6074" date="2009-10-20T14:02:00.746-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:34.565-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:19.090-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6261"/>
        <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
          <criterion comment="Patch ESX400-200906411-SG is not installed" test_ref="oval:org.mitre.oval:tst:10851"/>
          <criterion comment="Patch ESX400-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10872"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6261" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 4.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:4.0"/>
        <description>The operating system installed on the system is VMware ESX Server 4.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:59.848-04:00">DRAFT</status_change>
            <status_change date="2009-10-26T04:00:05.251-04:00">INTERIM</status_change>
            <status_change date="2009-11-16T04:00:17.778-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 4.0 is installed" test_ref="oval:org.mitre.oval:tst:10766"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5975" version="1" class="vulnerability">
      <metadata>
        <title>udev Netlink Message Validation Local Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185"/>
        <description>udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:08.426-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:5975" date="2009-10-20T14:03:00.817-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:31.582-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:17.343-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5895"/>
        <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
          <criterion comment="Patch ESX400-200906411-SG is not installed" test_ref="oval:org.mitre.oval:tst:10791"/>
          <criterion comment="Patch ESX400-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:9883"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5895" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 4.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:4.0"/>
        <description>The operating system installed on the system is VMware ESX Server 4.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:08.157-04:00">DRAFT</status_change>
            <status_change date="2009-10-26T04:00:04.172-04:00">INTERIM</status_change>
            <status_change date="2009-11-16T04:00:15.958-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 4.0 is installed" test_ref="oval:org.mitre.oval:tst:10667"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6449" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos GSS-API SPNEGO Null Pointer Dereference and Invalid Memory Access Bugs Let Remote Denial of Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0845"/>
        <description>The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:28.961-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:20.646-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:01:00.504-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200908403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10799"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200906405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10839"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10641"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6339" version="1" class="vulnerability">
      <metadata>
        <title>MIT Kerberos SPNEGO and ASN.1 Multiple Remote Denial Of Service Vulnerabilities</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0844"/>
        <description>The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:29.248-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:15.316-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:48.896-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200908403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10799"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200906405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10839"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10641"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5483" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos ASN.1 GeneralizedTime Decoder Bug Lets Remote Users Execute Arbitrary Code</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846"/>
        <description>The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:28.755-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:03.599-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:18.308-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200908403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10799"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200906405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10839"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10641"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6026" version="1" class="inventory">
      <metadata>
        <title>VMWare ESX Server 3.0.3 is installed</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:3.0.3"/>
        <description>The operating system installed on the system is VMWare ESX Server 3.0.3.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:59.389-04:00">DRAFT</status_change>
            <status_change date="2008-11-03T04:00:24.411-05:00">INTERIM</status_change>
            <status_change date="2008-11-24T04:00:20.126-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMWare ESX Server 3.0.3 is installed" test_ref="oval:org.mitre.oval:tst:9327"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5887" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 3.5.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 3.5</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:3.5.0"/>
        <description>The operating system installed on the system is VMware ESX Server 3.5.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-06T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-06T16:04:27.225-05:00">DRAFT</status_change>
            <status_change date="2009-02-23T04:00:21.573-05:00">INTERIM</status_change>
            <status_change date="2009-03-16T04:00:14.681-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 3.5.0 is installed" test_ref="oval:org.mitre.oval:tst:9598"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5626" version="1" class="inventory">
      <metadata>
        <title>VMWare ESX Server 3.0.2 is installed</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:3.0.2"/>
        <description>The operating system installed on the system is VMWare ESX Server 3.0.2.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-06-16T18:08:34.992-04:00">DRAFT</status_change>
            <status_change date="2008-07-07T04:00:30.338-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:18.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMWare ESX Server 3.0.2 is installed" test_ref="oval:org.mitre.oval:tst:7674"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5506" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 4.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:4.0"/>
        <description>The operating system installed on the system is VMware ESX Server 4.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:28.111-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:03.888-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:18.591-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 4.0 is installed" test_ref="oval:org.mitre.oval:tst:10625"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <version_test id="oval:org.mitre.oval:tst:11154" version="1" comment="VMware ESX Server 4.0 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:5705"/>
      <state state_ref="oval:org.mitre.oval:ste:5574"/>
    </version_test>
    <patch56_test id="oval:org.mitre.oval:tst:11288" version="1" comment="Patch ESX400-200911223-UG  is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:6482"/>
    </patch56_test>
    <patch56_test id="oval:org.mitre.oval:tst:11177" version="1" comment="Patch ESX350-200910403-SG is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:7207"/>
    </patch56_test>
    <patch56_test id="oval:org.mitre.oval:tst:10749" version="1" comment="Patch ESX400-200911223-UG is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:7145"/>
    </patch56_test>
    <version_test id="oval:org.mitre.oval:tst:10828" version="1" comment="VMware ESX Server 4.0 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:5705"/>
      <state state_ref="oval:org.mitre.oval:ste:5425"/>
    </version_test>
    <patch56_test id="oval:org.mitre.oval:tst:10871" version="1" comment="Patch ESX400-200906411-SG is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:6294"/>
    </patch56_test>
    <patch56_test id="oval:org.mitre.oval:tst:10674" version="1" comment="Patch ESX400-200906407-SG is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:6412"/>
    </patch56_test>
    <version_test id="oval:org.mitre.oval:tst:10766" version="1" comment="VMware ESX Server 4.0 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:5705"/>
      <state state_ref="oval:org.mitre.oval:ste:5443"/>
    </version_test>
    <patch56_test id="oval:org.mitre.oval:tst:10872" version="1" comment="Patch ESX400-200906407-SG is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:7276"/>
    </patch56_test>
    <patch56_test id="oval:org.mitre.oval:tst:10851" version="1" comment="Patch ESX400-200906411-SG is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:6934"/>
    </patch56_test>
    <version_test id="oval:org.mitre.oval:tst:10667" version="1" comment="VMware ESX Server 4.0 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:5705"/>
      <state state_ref="oval:org.mitre.oval:ste:4952"/>
    </version_test>
    <patch56_test id="oval:org.mitre.oval:tst:9883" version="1" comment="Patch ESX400-200906407-SG is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:7295"/>
    </patch56_test>
    <patch56_test id="oval:org.mitre.oval:tst:10791" version="1" comment="Patch ESX400-200906411-SG is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:7164"/>
    </patch56_test>
    <version_test id="oval:org.mitre.oval:tst:9327" version="1" comment="VMWare ESX Server 3.0.3 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:5705"/>
      <state state_ref="oval:org.mitre.oval:ste:4164"/>
    </version_test>
    <version_test id="oval:org.mitre.oval:tst:9598" version="1" comment="VMware ESX Server 3.5.0 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:5705"/>
      <state state_ref="oval:org.mitre.oval:ste:4747"/>
    </version_test>
    <version_test id="oval:org.mitre.oval:tst:7674" version="1" comment="VMWare ESX Server 3.0.2 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:5705"/>
      <state state_ref="oval:org.mitre.oval:ste:3209"/>
    </version_test>
    <version_test id="oval:org.mitre.oval:tst:10625" version="1" comment="VMware ESX Server 4.0 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:5705"/>
      <state state_ref="oval:org.mitre.oval:ste:5441"/>
    </version_test>
    <patch56_test id="oval:org.mitre.oval:tst:10839" version="1" comment="Patch ESX400-200906405-SG is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:6840"/>
    </patch56_test>
    <patch56_test id="oval:org.mitre.oval:tst:10799" version="1" comment="Patch ESX303-200908403-SG is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:7071"/>
    </patch56_test>
    <patch56_test id="oval:org.mitre.oval:tst:10641" version="1" comment="Patch ESX350-200906407-SG is not installed" check_existence="none_exist" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:7246"/>
    </patch56_test>
  </tests>
  <objects>
    <patch56_object id="oval:org.mitre.oval:obj:6482" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX400-200911223-UG</patch_name>
    </patch56_object>
    <patch56_object id="oval:org.mitre.oval:obj:7207" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX350-200910403-SG</patch_name>
    </patch56_object>
    <patch56_object id="oval:org.mitre.oval:obj:7145" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX400-200911223-UG</patch_name>
    </patch56_object>
    <patch56_object id="oval:org.mitre.oval:obj:6294" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX400-200906411-SG</patch_name>
    </patch56_object>
    <patch56_object id="oval:org.mitre.oval:obj:6412" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX400-200906407-SG</patch_name>
    </patch56_object>
    <patch56_object id="oval:org.mitre.oval:obj:7276" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX400-200906407-SG</patch_name>
    </patch56_object>
    <patch56_object id="oval:org.mitre.oval:obj:6934" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX400-200906411-SG</patch_name>
    </patch56_object>
    <patch56_object id="oval:org.mitre.oval:obj:7295" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX400-200906407-SG</patch_name>
    </patch56_object>
    <patch56_object id="oval:org.mitre.oval:obj:7164" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX400-200906411-SG</patch_name>
    </patch56_object>
    <version_object id="oval:org.mitre.oval:obj:5705" version="1" comment="The single version object." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx"/>
    <patch56_object id="oval:org.mitre.oval:obj:6840" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX400-200906405-SG</patch_name>
    </patch56_object>
    <patch56_object id="oval:org.mitre.oval:obj:7071" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX303-200908403-SG</patch_name>
    </patch56_object>
    <patch56_object id="oval:org.mitre.oval:obj:7246" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX350-200906407-SG</patch_name>
    </patch56_object>
  </objects>
  <states>
    <version_state id="oval:org.mitre.oval:ste:5574" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <release datatype="version">4.0.0</release>
    </version_state>
    <version_state id="oval:org.mitre.oval:ste:5425" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <release datatype="version">4.0.0</release>
    </version_state>
    <version_state id="oval:org.mitre.oval:ste:5443" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <release datatype="version">4.0.0</release>
    </version_state>
    <version_state id="oval:org.mitre.oval:ste:4952" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <release datatype="version">4.0.0</release>
    </version_state>
    <version_state id="oval:org.mitre.oval:ste:4164" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <release datatype="version">3.0.3</release>
    </version_state>
    <version_state id="oval:org.mitre.oval:ste:4747" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <release datatype="version">3.5.0</release>
    </version_state>
    <version_state id="oval:org.mitre.oval:ste:3209" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <release datatype="version">3.0.2</release>
    </version_state>
    <version_state id="oval:org.mitre.oval:ste:5441" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <release datatype="version">4.0.0</release>
    </version_state>
  </states>
</oval_definitions>